China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A highly sophisticated malware campaign, linked to Chinese threat actors, has expanded its reach with the introduction of a new variant dubbed LONGLEASH. This development marks a significant escalation in the ongoing ORB Network expansion, which has been causing widespread concern among cybersecurity experts and organizations worldwide.

The ORB Network is a complex web of interconnected systems, used by China-linked threat actors to launch targeted attacks on high-profile targets. The network’s architecture is built around UAT-7810, an AI-powered malware framework that enables sophisticated intrusion techniques. LONGLEASH, the latest addition to this arsenal, represents a significant upgrade in capabilities and stealth.

ORB Network’s primary function is to enable lateral movement within compromised networks, allowing attackers to move undetected across systems and exfiltrate sensitive data. This can be achieved through AI-driven reconnaissance, where UAT-7810 maps out target environments, identifies vulnerabilities, and executes tailored attacks with precision. LONGLEASH appears to have been designed to improve the malware’s ability to evade detection, exploiting existing weaknesses in security software to avoid triggering traditional defenses.

One of the most concerning aspects of this development is its potential impact on organizations that rely on AI-driven security tools for threat detection. As these models are trained on vast amounts of data, they can identify patterns and anomalies indicative of malicious activity. However, they also risk being outsmarted by sophisticated attacks like LONGLEASH, which might even use the same AI techniques to evade detection.

The introduction of LONGLEASH highlights the evolving nature of malware development in the ORB Network. As threat actors continually update their tools, organizations must stay vigilant and adapt their security strategies accordingly. This means implementing a multi-layered approach that incorporates behavioral analysis, endpoint detection, and continuous monitoring, rather than relying solely on signature-based detection.

In light of this development, it’s essential for security teams to review their defenses and consider the limitations of traditional AI-powered security solutions. Organizations should also prioritize incident response planning, ensuring they have robust protocols in place to detect and respond quickly to potential ORB Network attacks. By staying informed about emerging threats and continually updating their security posture, organizations can better protect themselves against the evolving tactics employed by China-linked threat actors.


Source: The Hacker News — 2026-07-08